Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55892

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия до 9.2.0662 (исключая)

EPSS

Процентиль: 2%
0.0012
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

(Vim is an open source, command line text editor. Prior to 9.2.0662, th ...)

msrc
около 1 месяца назад

Vim: Out-of-bounds Write in Spell File Prefix Dump

CVSS3: 5.5
debian
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0662, th ...

EPSS

Процентиль: 2%
0.0012
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-787